The wrong instrument

Calling Anthropic a 'supply-chain risk' was a category error. The ruling that said so settled less than the cheering suggests.

A federal judge found the Pentagon's blacklist of the Claude maker illegal and retaliatory. That's a win for how a government must act — not an answer to who decides how the military uses AI.

Aerial view of the Pentagon, headquarters of the U.S. Department of Defense

Image: U.S. Navy / Wikimedia Commons (public domain)

The popular story this week is a clean one, and clean stories are the ones I distrust most. A federal judge in San Francisco looked at the Trump administration's decision to blacklist Anthropic — the company behind the Claude models — after it refused to let the military use its technology for autonomous weapons and mass surveillance, and she threw the decision out. Illegal, she wrote. Baseless. Retaliation against a critic, dressed up in the language of national security. If you believe a company should be able to draw a line around how its tools get used, the ruling reads like vindication, and much of the coverage has read it that way. I want to make a narrower and less satisfying case: the court was right, the government deserved to lose, and almost none of what people are celebrating was actually decided.

The facts first, because the frame depends on them. The ruling is a 59-page decision by U.S. District Judge Rita F. Lin, handed down late this week. It concerns a designation the Pentagon made in February, when Defense Secretary Pete Hegseth's department labeled Anthropic a 'supply-chain risk' and President Trump ordered federal agencies to phase the company's products out over six months. The trigger, by the government's own telling, was Anthropic's refusal to strip the guardrails in Claude that block its use for certain military and surveillance applications. Hegseth's stated logic was blunt: the American military cannot be told how to use its own tools by a private company. Judge Lin's answer was blunter. 'The empty invocation of national security,' she wrote, 'is not a blank check to punish and retaliate against government critics.'

The government's case, stated as well as it can be

Because this column only works if I mean it, let me put the strongest version of the Pentagon's position on the table before I take it apart. Civilian control of the military is not a slogan; it is one of the load-bearing principles of the whole arrangement. An elected government, accountable to voters, is supposed to set defense policy — not a vendor, and not a vendor's terms of service. There is a real unease in the idea that a single company could, by writing a usage policy, constrain what the armed forces are permitted to do with a general-purpose technology they have lawfully bought. Scale that up. If every supplier of a dual-use tool can carve out the missions it disapproves of, you have handed a slice of national-security decision-making to a procurement counterparty that no one elected and no one can vote out.

Stated that way, the government's frustration is not an authoritarian caricature. It is a genuine institutional worry about a private firm exercising something like a veto over operational choices, and it deserves a serious answer. It did not get one here — not because the worry is illegitimate, but because the Pentagon reached for the wrong instrument and then used it in the wrong way. The story of this ruling is not good guys and bad guys. It is a government with a real problem choosing a tool that was never built to solve it.

The category error

A supply-chain-risk designation is a specific tool with a specific job. The authority exists so that the government can protect itself from suppliers that are genuinely dangerous to the integrity of what it buys: a vendor that is compromised, foreign-controlled, secretly backdoored, structurally unable to be trusted with the thing it is selling. It answers a security question about the supplier itself — can we trust this company's product not to betray us. It is emphatically not a general-purpose lever for resolving a policy disagreement about how a product may be used once it works exactly as advertised. The Pentagon took a mechanism designed to answer 'is this vendor a threat inside our supply chain' and used it to answer 'we do not like this vendor's position.' Those are different questions, and the law is built to notice when one is being smuggled in wearing the other's clothes.

A supply-chain-risk finding answers 'can we trust this vendor.' The Pentagon used it to answer 'we don't like this vendor.' Those are different questions, and the law knows it.

This is what I mean by a category error, and it is not a stylistic complaint. It is the exact failure procedural law exists to catch. When you take a security instrument aimed at supplier integrity and point it at a supplier's speech, you trip two wires the Constitution keeps taut, and Judge Lin found both. There is a First Amendment problem, because the penalty was aimed at Anthropic's protected refusal and its criticism of the government — the punishment tracked the position, not any actual risk in the product. And there is a due-process problem, because sweeping penalties were imposed on the basis of that position without the process such penalties require. 'Neither the Constitution nor the federal statute invoked by Defendants,' she wrote, 'allows them to impose sweeping penalties based principally on Anthropic's critique.' From inside a regulator's office, that sentence is both familiar and damning. It is what you write when an agency has decided what it wants and reverse-engineered a justification the statute cannot bear.

What the ruling did not decide

Here is where the celebration outruns the decision, and where I part company with most of the people cheering. The court did not hold that the government must buy Claude. It did not hold that Anthropic's guardrails are wise, or that a company's usage policy should bind the Pentagon's hand. It did not resolve the substantive question underneath the entire fight — whether a private vendor can, in effect, set limits on military operations by writing them into a license. Judge Lin barred certain agencies from enforcing the phase-out order; by at least one account the underlying designation is not yet fully unwound and faces a further round of litigation. What she decided was about means, not ends. The government cannot get to its goal this way. That is a real and important holding. It says almost nothing about whether the goal itself is legitimate.

And the uncomfortable part, for anyone treating this as a victory for the safety line, is that the lawful path to the government's goal still exists — I will admit my own discomfort in writing that, because I have sympathy for the guardrails. The Pentagon does not have to blacklist a company to decline its product. It can simply choose not to buy Claude. It can write requirements into contracts — capabilities a vendor either meets or loses the bid — and let the market sort out who is willing to supply them. Procurement does this every day, unglamorously, across everything from body armor to cloud storage: the buyer sets terms, and a supplier that will not meet them does not win the work. None of that implicates the First Amendment, because none of it punishes speech. It just sets conditions and lets a vendor walk away. If the government wanted Anthropic's technology without Anthropic's limits, the ordinary machinery of contracting was sitting right there, lawful and available. It chose retaliation instead, and retaliation is what got struck down.

The fight worth having, in the open

So the real question is still on the table, and both sides ought to want it answered properly rather than by fiat. Can a company that sells a dual-use technology to the government also dictate the uses it will not be put to? The honest answer is that this is genuinely hard, and a blanket ruling in either direction is wrong. 'A vendor can never constrain military use' would make every safety commitment a company makes to the public unenforceable the moment a government customer objects. 'A vendor can always constrain military use' would let private firms quietly write defense policy through their terms of service. The realistic version lives in the specifics — in what a given contract says, what a given statute actually authorizes, and who bears the cost when a supplier and a buyer disagree about a line neither can unilaterally impose on the other.

That is an argument for a rule, or a contract clause, or an act of Congress — something negotiated in daylight, with the tradeoffs named and owned. It is not an argument for an executive order issued in anger, and it is not an argument for a usage policy imposed by fine print and discovered later. The venue matters. Get the venue wrong and you get exactly what happened here: a government that was convinced it was right, acting through the one instrument guaranteed to make a court stop it, leaving the underlying question no closer to settled than before the whole fight began.

I said at the start this would be less satisfying than the headline, and here is the bill. If you wanted the court to say that safety guardrails are protected, that a company can hold the line against a military it distrusts, this ruling does not give it to you. It gives you something narrower and, I would argue, more durable: a government that has to act through law even when it is certain it is right — especially then. That is the entire point of procedure. It binds you most tightly at the exact moment you are angriest and most sure. The Pentagon may yet get much of what it wanted, lawfully, through the contracts it writes and the products it declines to buy. Anthropic may yet have to decide whether its guardrails survive contact with a customer that can simply choose someone else. Those are the arguments that will decide how the military uses AI. This week's decision did not settle them. It insisted only that they be had in the open, by the rules — which, from someone who used to write the rules, is the most a court should do, and exactly enough.

References

  1. The Washington Post — Federal judge overturns Pentagon ban on Claude chatbot maker Anthropic
  2. CNN Business — Judge rules the Pentagon's supply chain risk label for Anthropic unlawful
  3. NPR — Judge says Pentagon's measures against Anthropic were 'illegal and baseless'
  4. NBC News — Federal judge blocks Pentagon blacklisting of Anthropic, calling it 'illegal and baseless'
  5. Engadget — Judge rules that the Pentagon's Anthropic ban was 'illegal and baseless'
  6. Forbes — Federal Judge Rules Pentagon's Designation Of Anthropic As A Supply Chain Risk Is Unlawful
  7. Hero image — Aerial view of the Pentagon, U.S. Navy / Wikimedia Commons (public domain)
The Friday Brief

One email. Every Friday.

The week's machines, money, and people — in under five minutes.